Windows DNS Server Remote Code Execution Vulnerability
MonitorCVSS 6.8CVE-2026-50426Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredHigh
ComplexityLow
User InteractionNone needed
Summary
A path traversal vulnerability in Windows DNS Server allows an authorized attacker with administrative privileges and adjacent network access to execute arbitrary code on the DNS server. The vulnerability exists across Windows Server 2016, 2019, 2022, 2025, and Windows 10 versions 1607 and 1809. Microsoft has released patches for all affected products in the July 2026 security update.
What this means
What could happen
An attacker with adjacent network access and high-level administrative privileges could execute arbitrary code on a Windows DNS server, potentially disrupting name resolution services or gaining control of the server for lateral movement within your network.
Who's at risk
Windows Server administrators responsible for DNS services (Windows Server 2016, 2019, 2022, 2025) and IT staff managing Windows 10 endpoints with DNS Server roles. This affects on-premises DNS infrastructure commonly deployed in utilities for internal name resolution.
How it could be exploited
An attacker on the same network segment (adjacent network) with administrative credentials could exploit a path traversal flaw in the DNS Server service to execute arbitrary code. The attacker would need both network proximity and high-privilege credentials to exploit this vulnerability.
Prerequisites
- Attacker must have network access to the same network segment as the DNS server (adjacent network)
- Attacker must have administrator-level credentials on the DNS server or its domain
- DNS Server service must be running
Requires high-level privileges (administrator)Requires adjacent network accessAffects critical DNS infrastructureLow exploit probability (EPSS 0.4%)
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDIf immediate patching is not possible, restrict network access to DNS Server to only authorized administrative workstations using firewall rules or network segmentation
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Windows update for July 2026 (or the latest available monthly security update) to all affected Windows Server and Windows 10 systems running DNS Server
Long-term hardening
0/1HARDENINGAudit DNS Server administrative accounts and enforce strong authentication (such as multi-factor authentication) for any remote administration
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/0fc6f179-6739-4a32-ad15-f2a774d7eca7Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.